HackerFeeds

CyberSecurity News

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

The Hacker News
· August 26, 2026

AI summary

Cybersecurity researchers have revealed a new phishing toolkit called NovaCookies, which is used to capture Microsoft 365 authenticated sessions. This adversary-in-the-middle toolkit acts as a proxy to redirect Microsoft 365 sign-ins. The NovaCookies service is subscription-based, costing $320 per month, and is described as a phishing platform. It abuses legitimate Docusign notifications to steal sessions. The toolkit is designed to intercept and capture authenticated sessions, allowing attackers to gain access to Microsoft 365 accounts.

Read the full article at The Hacker Newsthehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.